Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-254p-9j5r-3fvc

больше 3 лет назад

The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.

EPSS: Низкий
github логотип

GHSA-254m-79rf-mxh7

больше 3 лет назад

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).

EPSS: Низкий
github логотип

GHSA-254m-3cq9-8624

почти 4 года назад

Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-254j-mmc5-qhpx

больше 3 лет назад

Smashing Cross-site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-254j-3m2w-23xr

почти 4 года назад

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

EPSS: Низкий
github логотип

GHSA-254h-gvgq-x2xg

больше 1 года назад

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-254g-h6q6-4fxv

почти 4 года назад

Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.

EPSS: Низкий
github логотип

GHSA-254f-jwvx-j47x

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.

EPSS: Низкий
github логотип

GHSA-254f-c2wq-r664

больше 3 лет назад

IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

EPSS: Низкий
github логотип

GHSA-254c-893v-cfqr

7 месяцев назад

Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-254c-2j77-4hhm

больше 3 лет назад

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2549-xh72-qrpm

около 1 года назад

Mattermost Improper Validation of Specified Type of Input vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2549-r7rv-9g8p

около 2 лет назад

Information disclosure

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2549-f94w-jg6h

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2548-xwx6-3r34

около 2 лет назад

A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2548-q746-x5x6

почти 5 лет назад

Code injection in port-killer

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2548-2rfq-335j

больше 3 лет назад

An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.

EPSS: Низкий
github логотип

GHSA-2547-59jc-hhfr

10 месяцев назад

Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2546-h2cp-j8x8

больше 3 лет назад

An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175767. References: M-ALPS02696445.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2546-c9vw-hgfw

больше 3 лет назад

A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-254p-9j5r-3fvc

The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-254m-79rf-mxh7

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-254m-3cq9-8624

Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-254j-mmc5-qhpx

Smashing Cross-site Scripting vulnerability

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-254j-3m2w-23xr

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

1%
Низкий
почти 4 года назад
github логотип
GHSA-254h-gvgq-x2xg

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-254g-h6q6-4fxv

Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-254f-jwvx-j47x

Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-254f-c2wq-r664

IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-254c-893v-cfqr

Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-254c-2j77-4hhm

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2549-xh72-qrpm

Mattermost Improper Validation of Specified Type of Input vulnerability

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2549-r7rv-9g8p

Information disclosure

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2549-f94w-jg6h

Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.

CVSS3: 6.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2548-xwx6-3r34

A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2548-q746-x5x6

Code injection in port-killer

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
github логотип
GHSA-2548-2rfq-335j

An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2547-59jc-hhfr

Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment.

CVSS3: 8.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-2546-h2cp-j8x8

An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175767. References: M-ALPS02696445.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2546-c9vw-hgfw

A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу